Security & Compliance

Security You Can Review.
Compliance You Can Ask About.

Scryber is built for HIPAA-compliant use by neurology practices, with encryption, access controls, audit logs, and a Business Associate Agreement available before PHI is processed.

HIPAA-Compliant

Scryber maintains safeguards required by the HIPAA Security Rule and provides a Business Associate Agreement before PHI is processed.

Encryption & Access Controls

PHI is encrypted at rest and in transit, with role-based access controls and multi-factor authentication for users.

Audit-Friendly Workflows

Access and workflow events are logged so practices can review activity around clinical documentation and compliance workflows.

Data Handling

  • All PHI encrypted at rest (AES-256) and in transit (TLS 1.3)
  • No patient data used for model training — ever
  • Data residency in the United States
  • Automatic session timeouts and re-authentication policies

Access Controls

  • Role-based access — providers see only what they need
  • Single sign-on (SSO) support for enterprise practices
  • Access audit logs retained for 7 years

Compliance & Certifications

  • HIPAA Business Associate Agreement (BAA) available before PHI processing
  • Independent third-party penetration test completed
  • HITECH-compliant breach notification procedures

Operational Security

  • Incident response plan with defined SLAs
  • Security review materials available on request

Retention & Subprocessors

  • Ask for current encounter-audio retention and deletion terms before processing PHI
  • Ask how deletion requests are handled under the applicable customer agreement
  • Request current subprocessor and hosting details during security review

Security review

Need the details before you evaluate?

Ask for current retention and deletion terms, subprocessor information, BAA documentation, and security review materials before your practice processes PHI through Scryber.

Request security details

© 2026 Scryber. All rights reserved.